
- 01Going passwordless across an enterprise typically takes 24-36 months. Technology is ready; legacy applications, recovery flows, user education, and residual edge cases extend the timeline.
- 02Year 1 (foundation): modern IdP with WebAuthn/passkey support enabled, MFA universal across the workforce, passkey enrollment opt-in for early adopters, inventory of every authentication method in the estate.
- 03Year 2 (transition): passkey enrollment promoted as the default, password-less sign-in option, legacy apps migrated to SAML/OIDC, recovery flows tightened (recovery is the new attack surface).
- 04Year 3 (completion): passwordless is default for new accounts, remaining password-required apps catalogued and on a retirement plan, recovery hardened. Roadmaps die on legacy app inventory and recovery flow design — protect the program from skipping either step under deadline pressure.
Going passwordless across an enterprise typically takes 24 to 36 months. The technology is ready; the legacy applications, the recovery flows, the user education, and the residual edge cases are what extend the timeline.
Year 1 — Foundation
- 01Modern IdP with WebAuthn/passkey support enabled
- 02MFA universal across the workforce
- 03Passkey enrollment opt-in for early adopters
- 04Inventory of every authentication method in the estate
Year 2 — Transition
Passkey enrollment promoted as the default. Password-less sign-in option for sign-in flows. Legacy applications migrated to SAML/OIDC where they are not already. Password reset flows tightened (the recovery story is the new attack surface).
Year 3 — Completion
Password-less is the default for new accounts. Remaining password-required applications are explicitly catalogued and on a retirement plan. Recovery flows are reviewed and hardened. The remaining password population is the small set of legacy systems with no path forward — typically isolated and monitored as a result.
Where roadmaps die
The legacy app inventory is always larger than expected. The recovery flow always takes longer to design than expected. Plan for both, and protect the program from the temptation to skip either step under deadline pressure.


